RANSOMWARE activity against Philippine organizations accelerated sharply in the first eight months of 2026, with public claims already exceeding the combined total recorded in 2024 and 2025, according to the 2026 Philippine Threat Landscape Report by Check Point Exposure Management.
Check Point tracked 31 public ransomware claims involving Philippine organizations from January to August, compared with 26 for all of 2024 and 2025 combined. Nine claims were recorded in August alone, according to the report.
The report said 15 ransomware groups posted claims involving Philippine organizations during the period, compared with 12 in all of 2025. Ten groups appeared in the local dataset for the first time in 2026.
"The character of the threat, however, changed less than the volume," the report said. "Targeting remained opportunistic rather than sector-selective, and no single group or sector dominated the local picture."
Check Point said the increase appeared to be driven by broader participation and the use of pre-positioned access and commoditized intrusion pipelines rather than new attack techniques.
Qilin accounted for nine of the 31 claims, including four in August, making it the largest contributor to the month's spike. Its of local claims increased from 23 percent to 29 percent, the report said.
The report also identified a sharp increase in the number of sectors represented in ransomware claims. Finance and Business Services recorded six claims each, followed by Retail with five. Manufacturing and Telecommunications each recorded one claim in both the January-to-August 2025 and 2026 periods.
"Philippine claim volume remained low against regional peers," the report said, ranking the country 10th among 11 monitored Asia-Pacific markets and ahead only of Vietnam. However, it added that the Philippine increase was faster than the global trend in relative terms despite remaining small in absolute volume.
The broader threat picture included 264 cyber incidents affecting Philippine organizations during the first eight months of the year. Website defacement and information-system disruption accounted for 216 incidents, while ransomware, breach and data-leak incidents accounted for 48. Government agencies recorded the highest incident volume, while Financial Services had the highest concentration of ransomware, breach and data-leak activity.
The report also recorded 24,875 cases of exposed data among monitored Philippine organizations during the period. Customer credentials accounted for 41.9 percent of observed exposure cases, followed by payment card data at 23.6 percent.
Artificial intelligence was primarily associated with fraud and social engineering rather than technical intrusion during the reporting period. Check Point found no evidence that AI had been used to gain technical access to a Philippine organization.
"Within the activity reviewed, Check Point found no evidence that AI was used to gain technical access to a Philippine organization during the reporting period," the report said. "Its observed local role remained primarily in fraud and social engineering."
The report recommended that organizations prioritize potential business impact rather than simply incident volume, continuously address identity and session exposure, reduce exposure along common intrusion paths, strengthen third-party governance, govern AI adoption and access, and turn threat intelligence into defined response actions.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
